Maryland's HB 1202: Consent for Facial Recognition in Interviews
8 min read · updated August 11, 2026
Maryland House Bill 1202 of 2020, codified at Md. Code Ann., Labor and Employment § 3-717, took effect on 1 October 2020 and is one of the earliest state laws in the United States addressing biometric technology in hiring. It is also one of the shortest, which is why what it does not say matters as much as what it does.
The requirement and the four waiver elements
The section prohibits an employer from using certain facial recognition services for the purpose of creating a facial template during an applicant’s interview for employment, unless the applicant consents. Consent has a prescribed form: the applicant must sign a waiver that states four things.
- the applicant’s name;
- the date of the interview;
- that the applicant consents to the use of facial recognition during the interview; and
- whether the applicant read the consent waiver.
The fourth element is unusual and is easy to implement badly. It is not an attestation that the applicant read the waiver — it asks whether they did, which means the form must permit “no” as an answer and must still record a signature. A form that forces the affirmative is not the form the statute describes. The bill and its history are published by the Maryland General Assembly at mgaleg.maryland.gov.
What counts as a facial recognition service
The definition is the scoping mechanism and it is broader than “the software recognised the candidate”. A facial recognition service means technology that analyses facial features and is used for recognition or persistent tracking of individuals in still or video images. Two clauses, joined by “and”: the technology must analyse facial features, and it must be used for recognition or persistent tracking.
The operative act the statute regulates is the creation of a facial template — the machine-interpretable pattern derived from facial features. So the boundary is not whether a camera was pointed at a candidate; it is whether a template was created for recognition or tracking purposes.
That leaves a real question about the systems employers actually buy. A tool that scores emotional expression, engagement or “enthusiasm” from video analyses facial features but may not be used for recognition or persistent tracking of an individual, and may not create a template in the sense the statute has in mind. An identity-verification step that confirms the person in the interview is the person who applied plainly does create one. The first case is genuinely unresolved under this section; the second is not.
Three boundaries the section does not draw
“During an applicant’s interview”. The prohibition is tied to the interview. Facial analysis applied to a recorded video after the interview has ended, or to a video submitted as part of an application before any interview, sits outside the section on a literal reading. Whether a court would read it that way is untested, and building a compliance position on the gap is a decision to litigate the boundary rather than to comply with the rule.
Employees, not applicants. The section speaks of an applicant. Facial recognition applied to existing employees — time and attendance, access control, monitoring — is not addressed here at all.
Retention and deletion. Unlike Illinois’s biometric statute, § 3-717 says nothing about how long a template may be held, what security applies to it, or whether it may be disclosed. Consent is the whole of the regulation. That is a striking omission and it is the main reason to treat this section as a floor rather than as a compliance target.
The missing remedy, and where liability comes from instead
The section provides no penalty and names no enforcement agency, and it does not create an express private right of action. Whether one is implied under Maryland law has not been resolved by a published decision. That is the same structural gap as in Illinois’s video interview statute, and it produces the same practical conclusion: the statute is not where the financial risk lives.
The financial risk lives in three other places. Illinois’s Biometric Information Privacy Act carries statutory damages per violation and an express private right of action, and it applies to the collection of face geometry from Illinois residents regardless of where the employer sits — a national video-interview programme is exposed there long before it is exposed in Maryland. Texas and Washington have biometric statutes enforced by their attorneys general. And a facial analysis system that performs differently across demographic groups creates disparate-impact exposure under Title VII and under Maryland’s own Fair Employment Practices Act, which is entirely independent of whether a waiver was signed. A signed consent is not a consent to be discriminated against.
There is a further layer for candidates with disabilities. A facial analysis assessment can disadvantage an applicant whose facial movement, expression or eye contact differs for reasons connected to a disability, which engages the reasonable-accommodation duty under the ADA and state law. The AI hiring law overview covers that ground.
Maryland’s newer privacy law reaches further
Maryland is no longer a one-section jurisdiction on this. The Maryland Online Data Privacy Act, enacted in 2024 and applying from October 2025, is among the more restrictive of the US comprehensive privacy statutes, and two features change the analysis for anyone processing biometric data about Maryland residents.
First, it imposes a strict data minimisation rule rather than a notice-and-consent rule: collection of personal data is limited to what is reasonably necessary and proportionate to provide or maintain a product or service requested by the consumer, and for sensitive data the standard is stricter still — processing is limited to what is strictly necessary to provide or maintain a specific product or service requested. Biometric data is sensitive data. Under a strict-necessity standard, consent does not unlock processing that is not necessary, which is a materially different regime from § 3-717.
Second, it prohibits the sale of sensitive data outright, and requires data protection assessments for profiling that presents a reasonably foreseeable risk of unfair or deceptive treatment, disparate impact, or other substantial injury. The same structure appears in Virginia and Delaware, with different trigger language in each.